What is an SSL key?
SSL makes a website safe, so the address starts with https://. It uses two files. The certificate is the public ID card. The private key is a secret file that proves the certificate is yours. Keep the private key secret.
What is a passphrase?
A passphrase is a password that locks the private key file. If the key has one, Apache asks you to type it every time it starts. That is a problem if the server restarts by itself at night. Apache will wait for a person to type, and your site stays offline.
Steps
- Log in to your server with SSH as root.
- Go to the folder where your key is. The path varies. Common ones are
/etc/ssl/privateor/etc/pki/tls/private. - Back up the original key.
cp server.key server.key.orig
This makes a safe copy of the locked key.
- Run the OpenSSL command that writes a new key without a passphrase.
openssl rsa -in server.key.orig -out server.key
This reads the locked key, asks for the passphrase, and saves an unlocked copy as server.key.
- Type your current passphrase when asked. You see a message such as
writing RSA key. - Make the file readable only by root.
chmod 600 server.key
chown root:root server.key
These commands stop other users from reading the key.
- Test your Apache setup.
apachectl configtest
This checks your Apache settings for mistakes. It should say Syntax OK. On some systems the command is apache2ctl or httpd -t.
- Restart Apache.
systemctl restart httpd
This restarts the web server. On Debian and Ubuntu, use apache2 instead of httpd.
Check it
Apache should restart without asking for a password. Open your site with https:// to confirm.
How to check if a key has a passphrase
Open the key file as text. If the top line says ENCRYPTED, it has a passphrase.
Quick recap
- A passphrase locks your private key.
- Apache stops at startup to ask for it.
- Use
openssl rsa -in ... -out ...to remove it. - Back up first and set file permission to 600.
- Test and restart Apache.